Guides · Safety

Payment security explained

Most payment fraud does not break the bank's controls. It persuades you to approve the payment yourself. This guide covers both halves of the problem.

In short

Strong customer authentication requires two independent factors from the categories knowledge, possession and inherence before an online payment is approved. 3-D Secure is the protocol that carries this for card payments. These controls stop impersonation, but not payments you approve after being deceived. A chargeback is a card scheme agreement with a limited window, not a legal right.

On this page
Key factsSourced
What SCA is
Authentication using two or more independent elements from knowledge, possession and inherenceSource 1
When it applies
Accessing an account online, initiating an electronic payment, or any remote action implying fraud riskSource 2
Chargeback window
Usually around 120 days to raise oneSource 5
APP fraud reimbursement cap
£85,000, for UK Faster Payments and CHAPS transfersSource 7

Two different problems

Payment security covers two problems that look similar and are not.

The first is impersonation: somebody else uses your card or account. Banking rules and card networks have spent years reducing this, and they have been reasonably successful.

The second is deception: you make the payment yourself, having been convinced to. No authentication step catches this, because the authentication works exactly as designed.

Understanding which is which tells you what protection actually applies afterwards.

Strong customer authentication

In the United Kingdom, strong customer authentication is defined in law as "authentication based on the use of two or more elements that are independent, in that the breach of one element does not compromise the reliability of any other element"1. Those elements must fall into two or more of three named categories: knowledge, something known only by the payment service user; possession, something held only by that user; and inherence, something inherent to that user1.

Category Typical example
Knowledge A password or PIN
Possession A registered phone or a card reader
Inherence A fingerprint or face scan

A payment service provider must apply it "where a payment service user— (a) accesses its payment account online... (b) initiates an electronic payment transaction; or (c) carries out any action through a remote channel which may imply a risk of payment fraud or other abuses"2.

For remote payments there is an extra requirement: the authentication must include "elements which dynamically link the transaction to a specific amount and a specific payee"2. In practice this is why the approval prompt in a banking app shows the amount and the merchant. Reading that screen is the single most useful security habit available to a consumer.

The FCA summarises the purpose for consumers: the rules "aim to reduce the risk of a fraudster pretending to be you to steal your money"4. The rules took effect on 14 September 20193.

3-D Secure, and why some payments are not challenged

For card payments, the protocol carrying this is EMV 3-D Secure. EMVCo describes it as helping "payment card issuers and merchants around the world prevent card-not-present (CNP) fraud and increase the security of e-commerce payments" by exchanging data between merchant and issuer about "the transaction, payment method and device"6.

Not every payment produces a challenge. EMVCo notes that "For many transactions, this means consumers simply click 'Buy' and the payment is approved", with further authentication requested only for "higher-risk transactions"6.

The European Banking Authority recognised in June 2019 that protocols such as EMV 3DS provide a means to support strong customer authentication, by enabling two-factor authentication through methods including a one-time passcode, knowledge-based questions or biometrics6.

A payment going through without a prompt is therefore normal. It is not evidence that a site has bypassed anything.

Phishing and fake cashier pages

The second problem is social, and the patterns are well documented. The National Cyber Security Centre lists the signals that appear in most scam messages8.

  • Authority. "Is the message claiming to be from someone official? For example, your bank, doctor, a solicitor, or a government department."
  • Urgency. "Are you told you have a limited time to respond (such as 'within 24 hours' or 'immediately')?"
  • Emotion. "Does the message make you panic, fearful, hopeful or curious?"
  • Scarcity. "Is the message offering something in short supply, like concert tickets, money or a cure for medical conditions?"
  • Current events. "Are you expecting to see a message like this?"

The NCSC's advice when something looks wrong is to "contact the organisation directly" and not to "use the numbers or address in the message – use the details from their official website"8. It also notes that legitimate organisations "will never ask you to supply personal information via email, or call and ask you to confirm your bank account details"8.

A fake cashier page is the same attack applied to a payment screen. The page is a copy, the payment is real, and it goes somewhere else. Clone sites are covered in more detail in how to spot unsafe gambling sites.

Bank fraud controls and reimbursement

Where a transfer is made under deception, a separate route exists in the United Kingdom.

The Payment Systems Regulator describes authorised push payment fraud as happening "when you're tricked into sending money to a fraudster via bank transfer"7. Since 7 October 2024 the reimbursement requirement has applied to payments made on or after that date, covering UK bank transfers over Faster Payments and CHAPS, with a maximum claim of £85,0007.

Claims should be reported "as soon as possible, and within 13 months of making the fraudulent payment", with reimbursement due within five business days, or 35 business days where a firm needs more information7.

The scheme excludes card, cash and cheque payments, which have their own protections, and does not cover civil disputes7.

What a chargeback can and cannot do

Chargeback is often described as a guarantee. It is not.

MoneyHelper is direct: "Chargeback isn't legal protection like section 75, which applies in the UK. It's an agreement Visa, Mastercard and American Express have signed up to"5.

The Financial Ombudsman Service describes it as letting you "challenge and 'claw back' payments made using a debit or credit card", with each scheme setting its own rules, and notes you "usually have around 120 days to raise a chargeback about goods or services", though "Time limits might be longer or shorter depending on the circumstances"9.

Chargeback Section 75
Basis Card scheme agreement5 Statutory protection9
Cards covered Debit, credit and prepaid5 Credit card only9
Value limits None stated Cash price over £100 and not more than £30,0009
Typical window Around 120 days9 Longer, set by the Act

What neither route is designed to do is unwind a gambling loss. A completed wager is not a faulty good, and attempting to reverse it as one is a route to a closed account rather than a refund.

Storing as little as possible

The final layer is reducing what there is to steal.

The PCI Security Standards Council sets the data security standard that applies to "entities that store, process or transmit payment account data"10. Compliance is enforced by payment brands and acquirers rather than by the Council itself10.

From a consumer's side the equivalent principle is the same one, applied to your own footprint.

  • Keep balances where they are protected. The FSCS states that it "can't protect the money you have with e-money institutions and payment providers"11.
  • Remove stored cards from accounts you are not using.
  • Use a unique password per site and enable the strongest authentication offered.
  • Read the amount and payee on every approval prompt, since dynamic linking puts them there for exactly that reason2.

How the methods themselves differ is covered in casino payment methods compared, with method-by-method detail in the payments section.

KYC (know your customer)
Checks a gambling operator carries out to confirm a customer's identity and age, and sometimes their source of funds. Some regulators, such as Great Britain's Gambling Commission, require age and identity to be verified before a customer gambles.

If a payment has gone wrong, contact your bank using the details on its official website rather than any number sent to you.

Sources

  1. The Payment Services Regulations 2017, regulation 2 (interpretation)
    legislation.gov.uk · Published 19 July 2017 · Accessed 12 September 2026
  2. The Payment Services Regulations 2017, regulation 100 (authentication)
    legislation.gov.uk · Published 19 July 2017 · Accessed 12 September 2026
  3. Strong Customer Authentication
    Financial Conduct Authority · Accessed 12 September 2026
  4. Strong customer authentication (consumer guidance)
    Financial Conduct Authority · Accessed 12 September 2026
  5. EMV 3-D Secure
    EMVCo · Accessed 12 September 2026
  6. APP fraud reimbursement protections
    Payment Systems Regulator · Accessed 12 September 2026
  7. How to spot a scam email, text message or call
    National Cyber Security Centre · Accessed 12 September 2026
  8. Problems with goods and services: section 75 and chargeback
    Financial Ombudsman Service · Accessed 12 September 2026
  9. About us
    PCI Security Standards Council · Accessed 12 September 2026
  10. Pots, pockets, piggy banks and vaults: keeping track of your money (or e-money), and its FSCS protection
    Financial Services Compensation Scheme · Accessed 12 September 2026
18+Gambling involves financial risk

Gambling can cause harm

No game gives a guaranteed return, and losses cannot be won back by playing more. If gambling is affecting your money, work, sleep or relationships, support is available — including free services you can contact from the Maldives.

Editorial independence. This edition of KiraBet carries no affiliate links, no paid placements and no links to gambling operators. Nothing here is an invitation to gamble. Read the full disclosure or see how we review.